logo

Defying tunneling: A Wicked approach to detecting malicious network traffic

ID: 461f70dc-962e-5035-99ee-b01a2cd69cc0

STIX ID: report--461f70dc-962e-5035-99ee-b01a2cd69cc0

Feed Name: Red Canary

Threat Score
65/100

Date Published: 2025-02-12

Date Updated: 2026-04-29

Author: Tony Lambert

...
...

This report analyzes December 2024 malware configuration data (over 150,000 samples) to show that multiple RAT families commonly use reverse tunneling services and dynamic DNS providers to hide C2 infrastructure; notable domain preferences include ply.gg (Playit), duckdns.org, portmap.host, and No-IP domains. The authors describe their methodology (VirusTotal parsing and Synapse pivots), present per-family domain usage, and recommend detection/mitigation steps such as DNS sinkholing, allowlisting needed DDNS providers, and monitoring/blocking tunneling services while balancing business needs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.